Remix.run Logo
▲ lapcat 3 hours ago

So you prefer to accept the version of events where Aten somehow stumbled upon a macOS security vulnerability that allows apps without Full Disk Access to read the Messages database, a vulnerability that nobody else has reproduced and that Apple itself apparently doesn't recognize? Just because one writer said so?

▲cloudfudge an hour ago | parent [-]

If what the writer said was strictly true, Apple would be having a little security freakout about how Muse managed to bypass this OS control. My assumption is that the writer did not understand everything he was granting it permission to do, so he legitimately believes that he didn't grant it those permissions. But he did.

▲GeekyBear an hour ago | parent [-]

Apple's statement is that the permission is being abused to do things that users do not think are possible.

In this case, Meta explicitly promises that Muse will not read your messages even after you grant it disk permissions.

▲lapcat 4 minutes ago | parent [-]

> In this case, Meta explicitly promises that Muse will not read your messages even after you grant it disk permissions.

There's no reason to doubt this claim. The only person in the world who has claimed that Muse disrespects its own internal setting is the same person who claimed that he didn't grant Full Disk Access to Muse.

Ironically, Aten's own screenshot appears to show that he toggled the internal setting from "Off" to "Read only". In my own testing, it's "Off" by default, and the only way to change the internal setting is to enable Full Disk Access first.

Thus, the likeliest scenario is that Aten unthinkingly granted Full Disk Access to Muse, granted the Messages app permission, then had a change of heart, disabled Full Disk Access, and then forgot what he had done. Later, when he noticed that Muse had some of his messages, he went back and checked, and saw the FDA was disabled, forgetting that he had toggled it on and off.